Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

As a product owner, I want document separation of duties to meet AC-05 security control #434

Closed
2 of 6 tasks
shubhi-raft opened this issue Nov 21, 2020 · 1 comment
Closed
2 of 6 tasks
Assignees
Labels
DAC Django Admin Console DUPE possible duplicate security
Milestone

Comments

@shubhi-raft
Copy link
Collaborator

shubhi-raft commented Nov 21, 2020

Description:
This issue will deliver documentation and demo on how separation of duties will be maintained to meet security control, AC-05.

Acceptance Criteria:

  • Documentation user roles with list of permissions and account management to meet AC-05 is is documented in docs (with screenshots of Django Admin Control (DAC) if applicable)
  • Demo of user roles to show separation of duties using Django Admin Control (DAC)

Tasks:
Create a list of granular, specific work items that must be completed to deliver the desired outcomes of this issue

  • Task 1
  • Task 2
  • Task 3
  • Run Testing Checklist and confirm all tests pass

Notes:

  • AC-05 security control:
    The organization:
    a. Separates [at a minimum, data creation and control, software development and maintenance, and security functions];
    b. Documents separation of duties of individuals; and
    c. Defines information system access authorizations to support separation of duties.

  • To meet

  • document user roles with list of permissions, account management,

  • backend can demo separation of duties (demo of documented user role with permissions)

Supporting Documentation:
Please include any relevant log snippets/files/screen shots

  • Doc 1
  • Doc 2

Open Questions:

  • NA

Deliverable:

@shubhi-raft shubhi-raft changed the title As a product owner, I want to separation of duties to meet AC-05 security control As a product owner, I want separation of duties to meet AC-05 security control Dec 2, 2020
@shubhi-raft shubhi-raft added this to the Sprint 10 milestone Dec 9, 2020
@shubhi-raft shubhi-raft added the DAC Django Admin Console label Dec 27, 2020
@shubhi-raft shubhi-raft changed the title As a product owner, I want separation of duties to meet AC-05 security control As a product owner, I want document separation of duties to meet AC-05 security control Jan 21, 2021
@kniz-raft kniz-raft added the DUPE possible duplicate label Jan 26, 2021
@kniz-raft
Copy link

Duplicate with #587, moving to a different organizational method to track security control documentation (each security control family will be an epic, each control will be an issue under that epic)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
DAC Django Admin Console DUPE possible duplicate security
Projects
None yet
Development

No branches or pull requests

3 participants